QID 591267

QID 591267: Mitsubishi Electric Factory Automation Engineering Products (Update D) Multiple Vulnerabilities (ICSA-20-212-04)

AFFECTED PRODUCTS
The following products and versions are affected:
MI Configurator, Versions 1.004E and prior
Setting/monitoring tools for the C Controller module Versions 4.12N and prior
CPU Module Logging Configuration Tool, versions 1.100E and prior
Network Interface Board CC IE Control utility, Versions 1.29F and prior
Network Interface Board CC IE Field Utility, Versions 1.16S and prior
Network Interface Board MNETH utility, Versions 34L and prior
MR Configurator2, Versions 1.105K and prior
GX LogViewer, Versions 1.100E and prior
M_CommDTM-IO-Link, Versions 1.03D and prior

QID Detection Logic (Authenticated)
This QID checks for the Vulnerable version using windows registry keys.

Successful exploitation of this vulnerability may enable the reading of arbitrary files, cause a denial-of-service condition, and allow the execution of a malicious binary.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-20-212-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591267

    Software Advisories
    Advisory ID Software Component Link
    ICSA-20-212-02 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-20-212-02